Skip to main content

Vendor archive

cpanel CVEs

Beta · best-effort

428 CVEs tagged to vendor cpanel21 Critical, 106 High, 244 Medium, 57 Low, 0 Unrated.

CVE-2016-10860

Published Aug 1, 2019

cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10859

Published Aug 1, 2019

cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10858

Published Aug 1, 2019

cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10857

Published Aug 1, 2019

cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10856

Published Aug 1, 2019

cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10855

Published Aug 1, 2019

cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10854

Published Aug 1, 2019

cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10853

Published Aug 1, 2019

cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10852

Published Aug 1, 2019

cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10851

Published Aug 1, 2019

cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10850

Published Aug 1, 2019

cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9291

Published Aug 1, 2019

cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20900

Published Aug 1, 2019

cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20899

Published Aug 1, 2019

cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20898

Published Aug 1, 2019

cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20897

Published Aug 1, 2019

cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20896

Published Aug 1, 2019

cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20895

Published Aug 1, 2019

In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20894

Published Aug 1, 2019

cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20893

Published Aug 1, 2019

cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20892

Published Aug 1, 2019

cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20891

Published Aug 1, 2019

cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20890

Published Aug 1, 2019

cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20889

Published Aug 1, 2019

cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20888

Published Aug 1, 2019

cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 428 CVEsPage 13 of 18